Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Defense Layers: A Case Study

Posted on October 28, 2021 By Michael Kavka No Comments on Defense Layers: A Case Study

Recently, I have been wondering why a site such as mail[.]ru(and it’s subdomains) is being blocked by Microsoft Exploit Guard’s Network Protection setting and not Umbrella. Considering that Network Protection does not give an actual block page, and instead a generic access denied page, it seems that the order of things were to blame. I did some experimenting and testing along with research to come up with the following conclusions on the order of something being blocked:

  1. uBlock Origin
  2. Network Protection\Smartscreen from Microsoft
  3. Cisco Umbrella

This seems counterintuitive since Umbrella is a DNS level service but from what I have come across, the actual hitting of the Umbrella block page is actually a Man in the Middle redirect based on the DNS classification. Finding a true writeup on where in the connection attempt Umbrella’s redirect happens is difficult to find, as Cisco says it is a kernel driver redirect based on the DNS yet looking at when the Umbrella block screen actually does appear, it is a bit later on in the connection process compared to uBlock origin and Exploit Guard’s Network Protection setting.

uBlock origin uses a known list of bad domains as part of its blocking technology. This allows for known bad sites to be immediately blocked by it.

Umbrella classification of ggmail.com (blocked by ublock origin)

When I went to the above site it was blocked by uBlock origin, even before Network Protection was able to hit because the site was in its autoblock list. Effective but easy to get around. uBlock origin is great though for ad blocking.

Microsoft Exploit Guard’s Network Protection is another interesting situation. While Cisco’s classifications come from its own Talos group, Microsoft has its own threat intelligence team. This data feeds into items such as Network Protection and Smartscreen (which is part of Edge if turned on). Using the site mail[.]ru as our example here, mail[.]ru gets blocked by Smartscreen in Edge and Network Protection on Chrome/Firefox. In Edge you get the famous red block screen saying Smartscreen has blocked access to the site. In Chrome and Firefox, you only get an Access Denied page with no other information.

Both of these technologies actually check and block immediately following the three-way handshake (syn, syn-ack and ack) based on Microsoft’s Threat Intelligence. This block is before any data is transferred that can be redirected (which is where Umbrella’s block page comes in).

Umbrella classification of mail[.]ru (blocked by Exploit Guard Network Protection)

What happens here is that Umbrella’s DNS has classified the site, and Umbrella is ready to send the block page upon connection, but the connection never gets to the redirection point. In the case of mail[.]ru, Umbrella will block the site in Chrome or Firefox if Network Protection is not enabled on the machine due to it being in the custom Blocklist that we have(what does worry me is all threat intelligence platforms I can look up mail[.]ru on show that it is known to house malware across its series of IP addresses, and that Cisco does not classify it as a Malware site is odd to me, but that is something different to look into at a later time). This has been tested on a machine that does have Umbrella and does not have Microsoft Exploit Guard Network Protection enabled on it.

Just as an example of something that Cisco blocked that the others did not, I found someone who went to an obvious typo of gmail.com. It does show the difference in classifications of threat intelligence out there that it is classified as Malware by Cisco but must not be by Microsoft since Network Protection did not kick in on this site.

Umbrella classification of gmai.com (Blocked by Umbrella)

The results of all this show how multiple layers of defense can work together can compliment each other, and where things are actually being blocked. It also shows that Cisco Umbrella’s block page is independent of its classification and being a redirect happens well enough after the three-way handshake (which could be microseconds) for it to not show when Smartscreen/Network Protection feels a site is malicious.

 

Microsoft, Security Tags:Network Protection, Smartscreen, uBlock Origin, Umbrella, Web Filtering

Post navigation

Previous Post: Device vs. User
Next Post: Do well, not be “popular”

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Are you sure it is the execs? Ramblings
  • The one about banking passwords… Rants

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General
Are you sure it is the execs? Ramblings
The one about banking passwords… Rants

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • NPM Isn't Prepared For North Korean PolinRider Attack August 25, 2026 c0a15726-c5b1-4b0d-85e6-fe15553df9e2
  • New Zealand to pursue social media ban for children under 16 August 24, 2026
  • Alabama launches investigation into OpenAI’s hack of Hugging Face August 24, 2026 Lorenzo Franceschi-Bicchierai
  • Hackers target WordPress sites in miniOrange auth bypass attacks August 24, 2026 Bill Toulas
  • Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ August 24, 2026 Tim Starks
  • Bipartisan Senate bill aims to prepare energy sector for Q-Day August 24, 2026 djohnson
  • Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly August 24, 2026
  • Instinct’s powerful AI assistant is raising privacy and security concerns August 24, 2026 Sarah Perez
  • A quick video of how to use MSBuild.exe to target a .csproj file that has b… August 24, 2026
  • Iran-linked cyberattack shut down a UK power plant August 24, 2026
  • Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) August 24, 2026 Stephen Fewer
  • ReliaQuest confirms failed data-theft attack after ShinyHunters breach August 24, 2026 Bill Toulas

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • NPM Isn't Prepared For North Korean PolinRider Attack August 25, 2026 c0a15726-c5b1-4b0d-85e6-fe15553df9e2
  • New Zealand to pursue social media ban for children under 16 August 24, 2026
  • Alabama launches investigation into OpenAI’s hack of Hugging Face August 24, 2026 Lorenzo Franceschi-Bicchierai
  • Hackers target WordPress sites in miniOrange auth bypass attacks August 24, 2026 Bill Toulas
  • Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ August 24, 2026 Tim Starks
  • Bipartisan Senate bill aims to prepare energy sector for Q-Day August 24, 2026 djohnson
  • Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly August 24, 2026
  • Instinct’s powerful AI assistant is raising privacy and security concerns August 24, 2026 Sarah Perez
  • A quick video of how to use MSBuild.exe to target a .csproj file that has b… August 24, 2026
  • Iran-linked cyberattack shut down a UK power plant August 24, 2026
  • Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) August 24, 2026 Stephen Fewer
  • ReliaQuest confirms failed data-theft attack after ShinyHunters breach August 24, 2026 Bill Toulas
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General
  • Gatekeeping and Treatment of Others Rants

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.